VMware VASA是VMware公司的一个虚拟卷存储提供程序。 VASA 存在安全漏洞,该漏洞源于允许有权访问 FlashArray 上 vSphere/ESXi VMware 管理员的用户通过权限升级获得 root 访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Pure Storage | FlashArray Purity | 6.1.* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-36627 | 7.7 HIGH | FlashBlade Snapshot Scheduler |
| CVE-2023-31042 | 7.7 HIGH | FlashBlade Object Store Protocol |
| CVE-2023-28372 | 6.5 MEDIUM | FlashBlade Object Store Privileged Access |
| CVE-2023-32572 | 6.5 MEDIUM | FlashArray pgroup Retention Lock SafeMode Protection |
| CVE-2023-28373 | 4.4 MEDIUM | FlashArray SafeMode Immutable Vulnerability |
No comments yet